CVE-2025-20149

⚪ Do wiadomości

Przepełnienie bufora w Cisco IOS umożliwia lokalnemu atakującemu wywołanie awarii urządzenia.

CVSS
6.5
EPSS
0.1%
Exploit
none
Vendor
cisco
Opis źródłowy (NVD)

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

buffer-overflow dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2025-09-24 18:15:33 UTC
Ostatnia modyfikacja (NVD)2026-09-18 13:18:49 UTC
Referencje